Courseiva

MFA Enforcement with Conditional Access Grant Control

Your organization needs to enforce multi-factor authentication (MFA) for all users accessing sensitive applications. You plan to use Microsoft Entra ID Conditional Access. Which grant control should you configure?

Quick Answer

The answer is to configure the "Require multi-factor authentication" grant control. This is the correct choice because MFA enforcement with Conditional Access grant control directly addresses the need to verify user identity through a second factor, such as a phone call or app notification, without introducing additional requirements like device compliance or authentication strength. On the Microsoft Cybersecurity Architect exam, this question tests your ability to match a straightforward security requirement to the simplest effective control, often appearing as a baseline scenario where the trap is overcomplicating the solution by selecting "Require authentication strength" or "Require compliant device." A strong memory tip is to remember that when the goal is purely to enforce MFA, the simplest grant control is the correct one—think "MFA first, complexity later."

⚠ Common exam trap

Test-takers frequently confuse 'Require authentication strength' (which is a newer, more specific control for phishing-resistant MFA) with the general 'Require multi-factor authentication' control, leading them to select the more complex option when the question simply asks for MFA enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require multi-factor authentication

The question specifies a requirement to enforce MFA for all users accessing sensitive applications. In Microsoft Entra ID Conditional Access, the 'Require multi-factor authentication' grant control directly enforces Azure AD MFA (e.g., via Microsoft Authenticator, OATH tokens, or SMS) as the primary authentication method. This is the simplest and most direct control to meet the stated goal of requiring MFA, without adding additional constraints like device compliance or authentication strength levels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require multi-factor authentication

    Why this is correct

    This grant control directly enforces MFA.

  • Require authentication strength (e.g., phishing-resistant MFA)

    Why it's wrong here

    Authentication strength is a separate feature, not a direct grant control for MFA.

  • Require device to be marked as compliant

    Why it's wrong here

    Device compliance is separate from MFA.

  • Use app enforced restrictions

    Why it's wrong here

    App enforced restrictions are for session control.

About these practice questions

One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization needs to enforce multi-factor authentication (MFA) for all users accessing Microsoft Entra ID integrated applications. However, users in the finance department should be exempted from MFA when accessing a specific legacy financial app that does not support modern authentication. What should you design?

easy
  • A.Enable security defaults for all users
  • B.Enable per-user MFA and exclude the finance department
  • C.Use Microsoft Entra Identity Protection to require MFA based on risk
  • D.Create a Conditional Access policy that requires MFA for all cloud apps except the legacy app

Why D: Conditional Access policies allow granular control over which applications require MFA. By creating a policy that requires MFA for all cloud apps except the legacy financial app, you can enforce MFA broadly while exempting the specific app that does not support modern authentication. This approach is more flexible and secure than per-user MFA or security defaults, as it can target specific applications and conditions.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.